fix: bound sys.stdin.read() to prevent OOM on oversized payloads - #3903
Open
Quratulain-bilal wants to merge 2 commits into
Open
fix: bound sys.stdin.read() to prevent OOM on oversized payloads#3903Quratulain-bilal wants to merge 2 commits into
Quratulain-bilal wants to merge 2 commits into
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
Attempts to cap event-runner stdin payloads at 10 MiB to reduce memory-exhaustion risk.
Changes:
- Adds chunked stdin readers.
- Applies them to CLI and generated event dispatchers.
Show a summary per file
| File | Description |
|---|---|
src/specify_cli/events.py |
Bounds generated dispatcher input. |
src/specify_cli/commands/event.py |
Bounds CLI event input. |
Review details
Tip
Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Suppressed comments (2)
src/specify_cli/events.py:317
- This call is emitted inside
_EVENTS_DISPATCHER_TEMPLATE, but_read_stdin_boundedwas defined in the host module before the template starts. The generated.specify/events.pytherefore has no such function and every standalone event invocation raisesNameErrorbefore dispatch. Move the constant and helper into the generated template (and remove the unused host-level copy).
payload = _read_stdin_bounded()
src/specify_cli/commands/event.py:19
sys.stdin.read(n)andlen(str)count characters rather than encoded bytes, so this does not enforce_MAX_STDIN_BYTES; UTF-8 non-ASCII payloads may read and retain substantially more than 10 MiB. Read bounded chunks fromsys.stdin.bufferand decode afterward with a defined truncation/error policy.
chunk = sys.stdin.read(min(max_bytes - total, 65536))
- Files reviewed: 2/2 changed files
- Comments generated: 2
- Review effort level: Balanced
…te limiting Address Copilot review feedback on PR github#3903: - Use sys.stdin.buffer.read() instead of sys.stdin.read() so the 10 MiB limit is enforced on raw bytes rather than Unicode code points (a 4-byte UTF-8 sequence now counts as 4 bytes, not 1 character). - Add regression tests for both the events module and CLI event runner: below-limit, exact-limit, oversized, multibyte UTF-8, empty stdin, TTY, and invalid UTF-8 replacement.
Quratulain-bilal
force-pushed
the
fix/bounded-stdin-read
branch
from
August 10, 2026 20:56
0f4f3d5 to
771cb50
Compare
| # Gemini/Tabnine/Devin which derive from the same protocol). | ||
| native_event = sys.argv[5] if len(sys.argv) >= 6 else "" | ||
| payload = sys.stdin.read() if not sys.stdin.isatty() else "{}" | ||
| payload = _read_stdin_bounded() |
The generated .specify/events.py files cannot import _read_stdin_bounded from the host module. Embed the bounded-read implementation directly in the template so it is self-contained.
Quratulain-bilal
force-pushed
the
fix/bounded-stdin-read
branch
2 times, most recently
from
August 17, 2026 20:36
0f4f3d5 to
2967161
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
sys.stdin.read()loads all of stdin into memory with no size limit. A malfunctioning agent hook or malicious process can pipe gigabytes of data into stdin, exhausting process memory before the payload is ever consumed.This affects both the CLI event runner (
commands/event.py) and the standalone events entry point (events.py).Fix
Cap stdin reads at 10 MiB using a bounded chunked read loop. The function reads in 64 KiB chunks and stops once the limit is reached, preventing unbounded memory allocation.
Testing